2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3402 | HIGH | 7.5 | 1.6% | Jul 2, 2020 | A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could ... |
| CVE-2020-7688 | HIGH | 7.8 | 0.5% | Jul 1, 2020 | The issue occurs because tagName user input is formatted inside the exec function is executed without any checks. |
| CVE-2020-6089 | HIGH | 7.8 | 2.7% | Jul 1, 2020 | An exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted AN... |
| CVE-2020-12498 | HIGH | 7.8 | 2.1% | Jul 1, 2020 | mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds ... |
| CVE-2020-12497 | HIGH | 7.8 | 14.7% | Jul 1, 2020 | PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-bas... |
| CVE-2020-8663 | HIGH | 7.5 | 1.5% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many conne... |
| CVE-2020-5907 | HIGH | 7.2 | 1.4% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorize... |
| CVE-2020-5906 | HIGH | 8.1 | 1.2% | Jul 1, 2020 | In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the acces... |
| CVE-2020-5904 | HIGH | 8.8 | 0.6% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSR... |
| CVE-2020-5899 | HIGH | 7.8 | 0.2% | Jul 1, 2020 | In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the dat... |
| CVE-2020-4420 | HIGH | 7.5 | 2.4% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe... |
| CVE-2020-4363 | HIGH | 7.8 | 0.5% | Jul 1, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buf... |
| CVE-2020-13383 | HIGH | 7.5 | 69.6% | Jul 1, 2020 | openSIS through 7.4 allows Directory Traversal. |
| CVE-2020-12605 | HIGH | 7.5 | 1.4% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers... |
| CVE-2020-12604 | HIGH | 7.5 | 1.7% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 cli... |
| CVE-2020-7689 | HIGH | 7.5 | 0.8% | Jul 1, 2020 | Data is truncated wrong when its length is greater than 255 bytes. |
| CVE-2020-5900 | HIGH | 8.8 | 0.5% | Jul 1, 2020 | In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for... |
| CVE-2020-12603 | HIGH | 7.5 | 1.4% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or... |
| CVE-2020-15478 | HIGH | 7.5 | 4.7% | Jul 1, 2020 | The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors. |
| CVE-2020-15476 | HIGH | 7.5 | 2.1% | Jul 1, 2020 | In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protoc... |
| CVE-2020-14167 | HIGH | 7.5 | 2.1% | Jul 1, 2020 | The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8... |
| CVE-2020-5972 | HIGH | 7.1 | 0.3% | Jun 30, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which local pointer variables are not initial... |
| CVE-2020-5971 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by usi... |
| CVE-2020-5970 | HIGH | 7.1 | 0.3% | Jun 30, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, wh... |
| CVE-2020-5968 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incor... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now